Hacker News new | ask | show | jobs
by Amadou 4574 days ago
I don't have the reference handy, but I recall an article from this past Summer that said the designers of the site had put security on the back-burner. Their plan was to get the system working and worry about security afterwards.

That really alarmed me. Being more than a little involved with security implementations over the last decade, the #1 rule is that you can't tack-on security afterwards. If you try, it will be fragile and ultimately ineffective. You absolutely must design with security as a major requirement from the start.

So, I am not surprised to see this report, it lines up exactly with what I've been expecting since Summer.

1 comments

Well then the #1 rule is also the most widely violated rule on the Internet.
Yep. Hence the constant stream of security issues.